CVE-2018-8836
MEDIUMWAGO 750 Series PLCs < 10 - Denial of Service via TCP Handshake Exploitation
Title source: llmDescription
Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during a TCP connection affecting the communications with commission and service tools. Specially crafted packets may also be sent to Port 2455/TCP/IP, used in Codesys management software, which may result in a denial-of-service condition of communications with commissioning and service tools.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/103726
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-18-088-01
Scores
CVSS v3
5.3
EPSS
0.0363
EPSS Percentile
88.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Details
CWE
CWE-404
Status
published
Products (8)
wago/750-829_firmware
< 10
wago/750-831_firmware
< 10
wago/750-852_firmware
< 10
wago/750-880_firmware
< 10
wago/750-881_firmware
< 10
wago/750-882_firmware
< 10
wago/750-885_firmware
< 10
wago/750-889_firmware
< 10
Published
Apr 03, 2018
Tracked Since
Feb 18, 2026